I see that pressure from both sides. As a CEO and a member of several boards, I push companies to use AI because I believe failing to adopt it effectively poses a serious competitive risk. But that same push for adoption makes governance more important, not less. CIOs are being asked to expand AI use while simultaneously managing risks that become harder to see as adoption spreads.
The strength of AI agents is that nontechnical employees can use them to build workflows and automate work. People in HR, finance, marketing, communications and other departments no longer need to wait for IT to develop every AI-enabled process. That accessibility creates enormous opportunity, but it also means AI can be deployed by employees who aren’t accustomed to evaluating security, compliance, privacy or legal risk.
Organizations therefore need to know what data an AI system is using, where that data came from, what decisions the system is making, and whether those uses align with company policies and legal requirements.